Impact
OpenImageIO can read indexed PSD files that contain transparency metadata. In versions before 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1 this causes the rawcolor path to calculate a channel count that is higher than the actual buffer array. The interleave_row function then indexes beyond the bounds of channel_buffers, resulting in a heap out‑of‑bounds read and an immediate crash of the process that is performing the read. The flaw does not grant an attacker execution of code or unauthorized data disclosure; the primary impact is a denial‑of‑service through application termination.
Affected Systems
The vulnerability affects the OpenImageIO library distributed by the Academy Software Foundation. All third‑party applications or pipelines that rely on OpenImageIO to process PSD files—and use the oiio:RawColor or psd:RawData features—are susceptible when their library version is any release older than 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score of < 1% signals a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves supplying a specially crafted indexed PSD file containing transparency metadata to a vulnerable host that uses OpenImageIO for image decoding. Because the flaw only causes a bounded memory read and a crash, it is not remotely exploitable for code execution but can be used to disrupt services that process user‑supplied images.
OpenCVE Enrichment